Debian Package Tracker
Register | Log in
Subscribe

thunderbird

mail/news client with RSS, chat and integrated spam filter support

Choose email to subscribe with

general
  • source: thunderbird (main)
  • version: 1:153.2.0esr-1
  • maintainer: Carsten Schoenert (DMD)
  • uploaders: Christoph Goehre [DMD]
  • arch: all amd64 arm64 i386 loong64 mips64el ppc64 ppc64el riscv64
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1:115.12.0-1~deb11u1
  • o-o-sec: 1:140.14.0esr-1~deb11u1
  • o-o-p-u: 1:115.14.0-1~deb11u1
  • oldstable: 1:140.12.0esr-1~deb12u1
  • old-sec: 1:140.15.0esr-1~deb12u1
  • old-p-u: 1:140.12.0esr-1~deb12u1
  • stable: 1:140.12.0esr-1~deb13u1
  • stable-sec: 1:140.15.0esr-1~deb13u1
  • stable-p-u: 1:140.15.0esr-1~deb13u1
  • testing: 1:140.14.0esr-1
  • unstable: 1:153.2.0esr-1
  • exp: 1:153.1.0esr-1
versioned links
  • 1:91.13.0-1~deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:115.12.0-1~deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:115.14.0-1~deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:115.16.0esr-1~deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:140.12.0esr-1~deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:140.12.0esr-1~deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:140.14.0esr-1~deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:140.14.0esr-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:140.15.0esr-1~deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:140.15.0esr-1~deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:153.1.0esr-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:153.2.0esr-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • thunderbird (129 bugs: 0, 113, 16, 0)
  • thunderbird-l10n-af
  • thunderbird-l10n-all
  • thunderbird-l10n-ar
  • thunderbird-l10n-ast
  • thunderbird-l10n-be
  • thunderbird-l10n-bg
  • thunderbird-l10n-br
  • thunderbird-l10n-ca
  • thunderbird-l10n-cak
  • thunderbird-l10n-cs
  • thunderbird-l10n-cy
  • thunderbird-l10n-da (1 bugs: 0, 0, 1, 0)
  • thunderbird-l10n-de
  • thunderbird-l10n-dsb
  • thunderbird-l10n-el
  • thunderbird-l10n-en-ca
  • thunderbird-l10n-en-gb
  • thunderbird-l10n-es-ar
  • thunderbird-l10n-es-es
  • thunderbird-l10n-es-mx
  • thunderbird-l10n-et
  • thunderbird-l10n-eu
  • thunderbird-l10n-fi
  • thunderbird-l10n-fr (2 bugs: 0, 1, 1, 0)
  • thunderbird-l10n-fy-nl
  • thunderbird-l10n-ga-ie
  • thunderbird-l10n-gd
  • thunderbird-l10n-gl
  • thunderbird-l10n-he
  • thunderbird-l10n-hr
  • thunderbird-l10n-hsb
  • thunderbird-l10n-hu
  • thunderbird-l10n-hy-am
  • thunderbird-l10n-id
  • thunderbird-l10n-is
  • thunderbird-l10n-it
  • thunderbird-l10n-ja
  • thunderbird-l10n-ka
  • thunderbird-l10n-kab
  • thunderbird-l10n-kk
  • thunderbird-l10n-ko
  • thunderbird-l10n-lt
  • thunderbird-l10n-lv
  • thunderbird-l10n-ms
  • thunderbird-l10n-nb-no
  • thunderbird-l10n-nl (1 bugs: 0, 1, 0, 0)
  • thunderbird-l10n-nn-no
  • thunderbird-l10n-pa-in
  • thunderbird-l10n-pl
  • thunderbird-l10n-pt-br
  • thunderbird-l10n-pt-pt
  • thunderbird-l10n-rm
  • thunderbird-l10n-ro
  • thunderbird-l10n-ru
  • thunderbird-l10n-sk
  • thunderbird-l10n-sl
  • thunderbird-l10n-sq
  • thunderbird-l10n-sr
  • thunderbird-l10n-sv-se
  • thunderbird-l10n-th
  • thunderbird-l10n-tr
  • thunderbird-l10n-uk
  • thunderbird-l10n-uz
  • thunderbird-l10n-vi
  • thunderbird-l10n-zh-cn
  • thunderbird-l10n-zh-tw
action needed
Debci reports failed tests high
  • unstable: pass (log)
    The tests ran in 0:05:07
    Last run: 2026-05-28T03:12:27.000Z
    Previous status: unknown

  • testing: fail (log)
    The tests ran in 0:03:08
    Last run: 2026-08-15T20:52:02.000Z
    Previous status: unknown

  • stable: pass (log)
    The tests ran in 0:03:10
    Last run: 2026-07-18T06:10:33.000Z
    Previous status: unknown

Created: 2026-08-15 Last update: 2026-09-13 20:01
13 security issues in forky high

There are 13 open security issues in forky.

13 important issues:
  • CVE-2026-16365: Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153, Thunderbird 153, Firefox ESR 140.15, and Thunderbird 140.15.
  • CVE-2026-75874: Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 140.15, and Thunderbird 153.2.
  • CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
  • CVE-2026-84120: Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
  • CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
  • CVE-2026-84122: Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
  • CVE-2026-84124: Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
  • CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
  • CVE-2026-84143: Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
  • CVE-2026-84145: Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
  • CVE-2026-84639: Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
  • CVE-2026-84640: A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
  • CVE-2026-84641: A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents can ultimately be persisted to prefs.js. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
Created: 2026-09-02 Last update: 2026-09-07 11:47
lintian reports 2 errors and 3 warnings high
Lintian reports 2 errors and 3 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-09-03 Last update: 2026-09-05 10:31
debian/patches: 1 patch with invalid metadata, 15 patches to forward upstream high

Among the 20 debian patches available in version 1:153.2.0esr-1 of the package, we noticed the following issues:

  • 1 patch with invalid metadata that ought to be fixed.
  • 15 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-09-03 06:02
Depends on packages which need a new maintainer normal
The packages that thunderbird depends on which need a new maintainer are:
  • libidl (#738870)
    • Build-Depends: libidl-dev
  • hunspell-kk (#879871)
    • Recommends: hunspell-kk
  • ifrench-gut (#1006643)
    • Recommends: myspell-fr-gut
  • uzbek-wordlist (#841696)
    • Recommends: hunspell-uz
Created: 2019-11-22 Last update: 2026-09-13 20:33
The package has not entered testing even though the delay is over normal
The package has not entered testing even though the 5-day delay is over. Check why.
Created: 2026-09-08 Last update: 2026-09-13 20:33
2 bugs tagged patch in the BTS normal
The BTS contains patches fixing 2 bugs, consider including or untagging them.
Created: 2026-09-02 Last update: 2026-09-13 20:30
Fails to build during reproducibility testing normal
A package building reproducibly enables third parties to verify that the source matches the distributed binaries. It has been identified that this source package produced different results, failed to build or had other issues in a test environment. Please read about how to improve the situation!
Created: 2026-08-28 Last update: 2026-09-13 20:01
1 new commit since last upload, is it time to release? normal
vcswatch reports that this package seems to have new commits in its VCS but has not yet updated debian/changelog. You should consider updating the Debian changelog and uploading this new version into the archive.

Here are the relevant commit logs:
commit 4340b21f1ecb0898d26219f1561747cabb0a9dac
Author: Christoph Goehre <chris@sigxcpu.org>
Date:   Thu Sep 10 18:15:24 2026 -0400

    d/control: re-Adding s390x architecture
    
    It was building flawless in the last six uploads to experimental, so
    just give it another chance.


https://salsa.debian.org/api/v4/projects/mozilla-team%2Fthunderbird API request failed: 401 Unauthorized at /srv/qa.debian.org/data/vcswatch/vcswatch line 410.
Created: 2026-09-12 Last update: 2026-09-12 00:02
AppStream hints: 1 warning normal
AppStream found metadata issues for packages:
  • thunderbird: 1 warning
You should get rid of them to provide more metadata about this software.
Created: 2021-12-22 Last update: 2021-12-22 06:06
testing migrations
  • This package is part of the ongoing testing transition known as auto-upperlimit-thunderbird. Please avoid uploads unrelated to this transition, they would likely delay it and require supplementary work from the release managers. On the other hand, if your package has problems preventing it to migrate to testing, please fix them as soon as possible. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
  • excuses:
    • Migrates after: allow-html-temp
    • Migration status for thunderbird (1:140.14.0esr-1 to 1:153.2.0esr-1): BLOCKED: Rejected/violates migration policy/introduces a regression
    • Issues preventing migration:
    • ∙ ∙ migrating thunderbird/1:153.2.0esr-1/amd64 to testing makes webext-eas4tbsync/4.17-2/amd64 uninstallable
    • ∙ ∙ migrating thunderbird/1:153.2.0esr-1/amd64 to testing makes webext-mailmindr/1.7.1-2/amd64 uninstallable
    • ∙ ∙ migrating thunderbird/1:153.2.0esr-1/amd64 to testing makes webext-quicktext/6.4.6-1/amd64 uninstallable
    • ∙ ∙ migrating thunderbird/1:153.2.0esr-1/amd64 to testing makes webext-tbsync/4.16-2/amd64 uninstallable
    • ∙ ∙ migrating thunderbird/1:153.2.0esr-1/amd64 to testing makes webext-xnotepp/4.6.51-1/amd64 uninstallable
    • ∙ ∙ migrating thunderbird/1:153.2.0esr-1/arm64 to testing makes webext-eas4tbsync/4.17-2/arm64 uninstallable
    • ∙ ∙ migrating thunderbird/1:153.2.0esr-1/arm64 to testing makes webext-mailmindr/1.7.1-2/arm64 uninstallable
    • ∙ ∙ migrating thunderbird/1:153.2.0esr-1/arm64 to testing makes webext-quicktext/6.4.6-1/arm64 uninstallable
    • ∙ ∙ migrating thunderbird/1:153.2.0esr-1/arm64 to testing makes webext-tbsync/4.16-2/arm64 uninstallable
    • ∙ ∙ migrating thunderbird/1:153.2.0esr-1/arm64 to testing makes webext-xnotepp/4.6.51-1/arm64 uninstallable
    • ∙ ∙ Implicit dependency: thunderbird allow-html-temp
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/t/thunderbird.html
    • ∙ ∙ Autopkgtest skipped on armhf: not installable (which is allowed)
    • ∙ ∙ Autopkgtest for thunderbird/1:153.2.0esr-1: amd64: Pass, arm64: Test triggered (failure will be ignored), i386: Pass, ppc64el: No tests, superficial or marked flaky ♻, riscv64: Test triggered (failure will be ignored)
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • ∙ ∙ 11 days old (needed 5 days)
    • Not considered
news
[rss feed]
  • [2026-09-05] Accepted thunderbird 1:140.15.0esr-1~deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Christoph Goehre)
  • [2026-09-04] Accepted thunderbird 1:140.15.0esr-1~deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Christoph Goehre)
  • [2026-09-02] Accepted thunderbird 1:153.2.0esr-1 (source) into unstable (Carsten Schoenert)
  • [2026-09-02] Accepted thunderbird 1:140.15.0esr-1~deb12u1 (source) into oldstable-security (Christoph Goehre)
  • [2026-08-26] thunderbird 1:140.14.0esr-1 MIGRATED to testing (Debian testing watch)
  • [2026-08-24] Accepted thunderbird 1:140.14.0esr-1~deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Carsten Schoenert)
  • [2026-08-24] Accepted thunderbird 1:140.14.0esr-1~deb11u1 (source) into oldoldstable-security (Carsten Schoenert)
  • [2026-08-23] Accepted thunderbird 1:140.14.0esr-1~deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Carsten Schoenert)
  • [2026-08-23] Accepted thunderbird 1:140.14.0esr-1~deb12u1 (source) into oldstable-security (Carsten Schoenert)
  • [2026-08-20] Accepted thunderbird 1:140.14.0esr-1 (source) into unstable (Carsten Schoenert)
  • [2026-08-19] Accepted thunderbird 1:153.1.0esr-1 (source) into experimental (Carsten Schoenert)
  • [2026-08-17] Accepted thunderbird 1:153.0.3esr-1 (source) into experimental (Carsten Schoenert)
  • [2026-08-11] thunderbird 1:140.13.0esr-2 MIGRATED to testing (Debian testing watch)
  • [2026-08-09] Accepted thunderbird 1:140.13.0esr-2~deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Carsten Schoenert)
  • [2026-08-09] Accepted thunderbird 1:140.13.0esr-2~deb11u1 (source) into oldoldstable-security (Carsten Schoenert)
  • [2026-08-07] Accepted thunderbird 1:140.13.0esr-2~deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Carsten Schoenert)
  • [2026-08-07] Accepted thunderbird 1:140.13.0esr-2~deb12u1 (source) into oldstable-security (Carsten Schoenert)
  • [2026-08-05] Accepted thunderbird 1:140.13.0esr-2 (source) into unstable (Carsten Schoenert)
  • [2026-08-04] Accepted thunderbird 1:140.13.0esr-1 (source) into unstable (Carsten Schoenert)
  • [2026-08-03] Accepted thunderbird 1:153.0.1esr-1 (source) into experimental (Carsten Schoenert)
  • [2026-06-23] thunderbird 1:140.12.0esr-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-22] Accepted thunderbird 1:152.0-1 (source) into experimental (Carsten Schoenert)
  • [2026-06-19] Accepted thunderbird 1:140.12.0esr-1~deb12u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Christoph Goehre)
  • [2026-06-19] Accepted thunderbird 1:140.12.0esr-1~deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Christoph Goehre)
  • [2026-06-18] Accepted thunderbird 1:140.12.0esr-1~deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Christoph Goehre)
  • [2026-06-18] Accepted thunderbird 1:140.12.0esr-1~deb12u1 (source) into oldstable-security (Debian FTP Masters) (signed by: Christoph Goehre)
  • [2026-06-17] Accepted thunderbird 1:140.12.0esr-1~deb11u1 (source) into oldoldstable-security (Christoph Goehre)
  • [2026-06-17] Accepted thunderbird 1:140.12.0esr-1 (source) into unstable (Christoph Goehre)
  • [2026-05-26] thunderbird 1:140.11.0esr-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-22] Accepted thunderbird 1:140.11.0esr-1~deb12u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Christoph Goehre)
  • 1
  • 2
bugs [bug history graph]
  • all: 340 343
  • RC: 0
  • I&N: 264 266
  • M&W: 76 77
  • F&P: 0
  • patch: 2
links
  • homepage
  • lintian (2, 3)
  • buildd: logs, exp, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
  • l10n (-, 73)
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2:1snap1-0ubuntu5
  • 403 bugs (4 patches)
  • patches for 2:1snap1-0ubuntu5

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing